fix-dependencies

作者: microsoft

使用npm audit修复当前分支上的所有漏洞。仅限本地分支——不涉及ADO/GitHub查询。

npx skills add https://github.com/microsoft/powerplatform-build-tools --skill fix-dependencies

Fix Dependencies

Fix all vulnerabilities on the current branch using npm audit. No user input required.

Scope: local branch only — no origin sync, no ADO queries, no Dependabot. For S360 / ADO / GitHub alerts use /security-alerts.


Step 1 — Audit

npm audit --json 2>&1

Build a fix list. For each vulnerability, apply the first matching rule:

ConditionAction
patched_version existsFix it — patch/minor/major all acceptable for security
inBundle: true, parent has newer versionUpgrade parent (Strategy B)
inBundle: true, no parent upgradePatch lock file directly (Strategy C)
patched_version: nullAccept risk, document, move on
scope: development + low severity + no patchAccept risk, move on

Known permanent accepted risk — do not flag: elliptic (GHSA-848j-6mx2-7j84) via rewiremock — dev-only, no patched version.


Step 2 — Fix (no pausing between fixes)

Strategy A — npm override (non-bundled transitive dep)

Add/update the entry in "overrides" in package.json, then:

npm view <pkg>@<version> version   # confirm version exists
# edit package.json overrides
npm install 2>&1
npm ls <pkg> 2>&1                  # confirm version took effect

Hard rules:

  • Never add "minimatch": "^3.x" as a flat override — infinite npm loop
  • ajv override must stay at ^6.x — v8 breaks ESLint
  • Do not change intentionally-pinned overrides (nanoid, electron-to-chromium, @types/node) unless explicitly asked

Strategy B — Direct dependency bump

Update the version in dependencies or devDependencies in package.json, then npm install.

Strategy C — Lock file patch (for inBundle: true packages)

# Find all paths for the package
node -e "
const l = require('./package-lock.json');
console.log(
  Object.keys(l.packages)
    .filter(k => k.endsWith('/<pkg>'))
    .map(k => k + ' -> ' + l.packages[k].version + ' inBundle:' + l.packages[k].inBundle)
    .join('\n')
);"

# Get safe version metadata
npm view <pkg>@<patched-version> dist.tarball dist.integrity --json

# Patch all matching entries
node -e "
const fs = require('fs');
const l = require('./package-lock.json');
Object.keys(l.packages)
  .filter(k => k.endsWith('/<pkg>'))
  .forEach(k => {
    l.packages[k].version = '<patched-version>';
    l.packages[k].resolved = '<tarball-url>';
    l.packages[k].integrity = '<integrity>';
  });
fs.writeFileSync('./package-lock.json', JSON.stringify(l, null, 2) + '\n');
console.log('Patched');
"
npm install 2>&1

Strategy D — Accept risk

Document in final summary. Do not block or ask.


Step 3 — Verify

npm audit 2>&1
npm run ci 2>&1

npm run ci functional tests will fail locally (require PA_BT_ORG_PASSWORD) — expected, not a blocker.

If npm run ci fails on a non-functional-test step (TypeScript error, lint, unit test), fix it and re-run before continuing. Do not commit a broken build.


Step 4 — Commit and PR (only if Step 3 passes)

git add package.json package-lock.json
git status   # confirm nothing accidental staged
git commit -m "chore: fix dependency vulnerabilities"

Then run /create-pr to create the pull request.


Final Summary

Print before handing off to /create-pr:

  • Fixed: package, old → new version, strategy used
  • Accepted risk: package, GHSA ID, reason

来自 microsoft 的更多技能

oss-growth
microsoft
OSS增长黑客角色
agent-framework-azure-ai-py
microsoft
使用Microsoft Agent Framework Python SDK(agent-framework-azure-ai)构建Azure AI Foundry代理。在创建使用AzureAIAgentsProvider的持久化代理、使用托管工具(代码解释器、文件搜索、网络搜索)、集成MCP服务器、管理对话线程或实现流式响应时使用。涵盖函数工具、结构化输出和多工具代理。
development
airunway-aks-setup
microsoft
在AKS上设置AI Runway——从裸集群到运行模型。涵盖集群验证、控制器安装、GPU评估、提供商设置和首次部署。适用场景:“设置AI Runway”、“接入AKS集群”、“安装AI Runway”、“airunway设置”、“将模型部署到AKS”、“在AKS上进行GPU推理”、“在AKS上配置KAITO”、“在AKS上运行LLM”、“在AKS上使用vLLM”、“在AKS上设置模型服务”、“AI Runway控制器”。
devops
appinsights-instrumentation
microsoft
使用Azure Application Insights对Web应用进行插桩的指南。提供遥测模式、SDK设置和配置参考。适用场景:如何对应用进行插桩、App Insights SDK、遥测模式、什么是App Insights、Application Insights指南、插桩示例、APM最佳实践。
devops
applicationinsights-web-ts
microsoft
使用Application Insights JavaScript SDK(@microsoft/applicationinsights-web)为浏览器/Web应用添加检测。用于真实用户监控(RUM)——页面视图、点击、AJAX/fetch依赖项、异常、自定义事件,以及与后端OpenTelemetry追踪关联的浏览器端GenAI代理追踪。涵盖SDK加载器脚本和npm设置、框架扩展(React、React Native、Angular)、点击分析、遥测初始化器,以及从浏览器发出的代理/工具/模型跨度所遵循的OTel GenAI语义约定。
devops
azure-ai-anomalydetector-java
microsoft
使用适用于 Java 的 Azure AI 异常检测器 SDK 构建异常检测应用程序。在实现单变量/多变量异常检测、时间序列分析或 AI 驱动的监控时使用。
development
azure-ai-language-conversations-py
microsoft
使用azure-ai-language-conversations Python SDK实现对话语言理解(CLU)。当使用ConversationAnalysisClient分析对话意图和实体、构建NLP功能或将语言理解集成到应用程序中时使用。
development
azure-ai-ml-py
microsoft
Azure Machine Learning SDK v2 for Python。用于机器学习工作区、作业、模型、数据集、计算资源和管道。 触发词:“azure-ai-ml”、“MLClient”、“工作区”、“模型注册表”、“训练作业”、“数据集”。
development